Cyber Threat Actor: NotPetya
| Actor Type | Location | Known Incidents |
Nation State
|
Russia
|
19 incidents |
|---|
Profile
NotPetya, also known as ExPetr, is a destructive malware campaign that has been publicly linked to actors operating from Russia. The threat actor is most commonly associated with the GRU’s Sandworm unit, a military cyber group attributed by the United States, United Kingdom, and European Union authorities. While the aliases refer to the same codebase, the activity is distinguished by its intent to cause widespread disruption rather than to generate financial gain. The actor’s known location is Russia, and its operations have been characterized as state‑sponsored rather than purely criminal.
The actor’s typical targeting has focused on Ukrainian institutions, especially government agencies, financial entities, and critical infrastructure, but the malware’s design allowed it to spill over into multinational corporations worldwide. Strategic objectives have been consistently described as disruption and sabotage, with no evidence of ransom payment being a genuine goal; the ransomware façade was used to conceal the wiper function. In terms of tactics, the actor leveraged the EternalBlue SMB exploit for initial access and lateral movement, employed credential‑dumping tools such as Mimikatz, and used legitimate administrative utilities like PsExec to propagate across networks. Initial infection frequently occurred through a compromised update mechanism of the Ukrainian tax software ME Doc, which served as a supply‑chain vector.
The most notable operation attributed to this actor occurred in June 2017, when NotPetya/ExPetr was released and rapidly encrypted master boot records on thousands of systems, affecting companies such as Maersk, Merck, FedEx TNT, and numerous Ukrainian entities. The attack caused extensive operational downtime, logistical delays, and financial losses estimated in the billions of dollars, underscoring its disruptive impact. Although the actor has not been tied to a series of distinct campaigns, the June 2017 event remains the primary publicly reported example of its capabilities and objectives. This summary reflects only the facts that are openly documented and avoids any speculation beyond those verified details.
